critical · CVSS v3 8.6 · CVSS v4 8.8
CVE-2026-105115
OpenAM versions prior to 16.1.3 allow unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX‑RPC SOAP interfac
Overview
OpenAM versions prior to 16.1.3 allow unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX‑RPC SOAP interface, potentially crashing the server or enabling code execution. The vulnerability is triggered by sending crafted SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name. It poses a critical risk to any deployment exposing the legacy SOAP endpoint.
Description
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Impact
The flaw compromises confidentiality, integrity, and availability of the affected OpenAM instance. Attackers can crash the server, enumerate the classpath, or chain gadget payloads for remote code execution, thereby impacting all users and services relying on the compromised authentication server.
Remediation
Apply the official patch to upgrade to OpenAM 16.1.3 or later. If upgrading is not immediately possible, disable the legacy JAX‑RPC SOAP endpoint or block access to /jaxrpc/* via firewall or application configuration. Ensure session identifiers are validated before processing SOAP requests.
Risk context
The vulnerability is rated critical with a CVSS v3 score of 8.6 and CVSS v4 score of 8.8. No EPSS data is available, but the lack of authentication makes the risk immediate for exposed instances.
Affected products
- ForgeRock OpenAM 16.1.2
- ForgeRock OpenAM 16.1.1
- ForgeRock OpenAM 16.1.0
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.6
- CVSS v4
- 8.8
- EPSS
- —